9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-28477
immer General
7.5
HIGH
EPSS
0.2%
2020 2 PoCs

This affects all versions of package immer.

CVE-2020-8617
BIND9 General
7.5
HIGH
EPSS
92.6%
2020 5 PoCs

Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an i

CVE-2020-28491
com.fasterxml.jackson.dataformat:jackson-dataformat-cbor General
7.5
HIGH
EPSS
0.4%
2020 2 PoCs

This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.

CVE-2020-35498
openvswitch General
7.5
HIGH
EPSS
5.8%
2020 CWE-400 1 PoC

A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

CVE-2020-7283
McAfee Total Protection (MTP) General
7.5
HIGH
EPSS
0.3%
2020 CWE-274 2 PoCs

Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to. This is achieved through running a malicious script or program on the target machine.

CVE-2020-12509
moni::tools General
7.5
HIGH
EPSS
1.1%
2020 CWE-22 1 PoC

In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path traversal in the camera-file module.

CVE-2020-26243
nanopb General
7.5
HIGH
EPSS
0.1%
2020 CWE-20 1 PoC

Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can leak memory if dynamic allocation is enabled and an oneof field contains a static submessage that contains a dynamic field, and the message being decoded contains the submessage multiple times. This is rare in normal messages, but it is a concern when untrusted data is parsed. This is fixed in versions 0.3.9.7 and 0.4.4. The following workarounds are available: 1) Set the option `no_unions` for the oneof field. This will generate fields as separate

CVE-2020-7791
i18n General
7.5
HIGH
EPSS
1.5%
2020 1 PoC

This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tags in src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs.

CVE-2020-5360
Dell BSAFE Micro Edition Suite General
7.5
HIGH
EPSS
2.1%
2020 CWE-127 1 PoC

Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability resulting in undefined behaviour, or a crash of the affected systems.

CVE-2020-4979
QRadar SIEM General
7.5
HIGH
EPSS
0.6%
2020 1 PoC

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.

CVE-2020-11243
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile General
7.5
HIGH
EPSS
0.2%
2020 1 PoC

RRC sends a connection establishment success to NAS even though connection setup validation returns failure and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

CVE-2020-27827
lldp/openvswitch General
7.5
HIGH
EPSS
0.5%
2020 CWE-400 1 PoC

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

CVE-2020-37011
Fonts Viewer General
7.5
HIGH
EPSS
0.0%
2020 CWE-787 1 PoC

Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially crafted TTF file with an oversized pattern to cause an infinite malloc() loop and potentially crash the gnome-font-viewer process.

CVE-2020-1983
libslirp General
7.5
HIGH
EPSS
0.1%
2020 CWE-416 1 PoC

A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.

CVE-2020-26184
Dell BSAFE Micro Edition Suite General
7.5
HIGH
EPSS
0.3%
2020 CWE-295 2 PoCs

Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.

CVE-2020-6086
Allen Bradley General
7.5
HIGH
EPSS
0.0%
2020 CWE-120 1 PoC

An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.If the Simple Segment Sub-Type is supplied, the device treats the byte following as the Data Size in words. When this value represents a size greater than what remains in the packet data, the device enters a fault state where communication with the device is lost and

CVE-2020-7763
phantom-html-to-pdf General
7.5
HIGH
EPSS
0.4%
2020 2 PoCs

This affects the package phantom-html-to-pdf before 0.6.1.

CVE-2020-12524
BTP Touch Panel General
7.5
HIGH
EPSS
0.3%
2020 CWE-400 1 PoC

Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service).

CVE-2020-7282
McAfee Total Protection (MTP) General
7.5
HIGH
EPSS
0.0%
2020 CWE-59 1 PoC

Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

CVE-2020-1045
ASP.NET Core 2.1 General
7.5
HIGH
EPSS
20.4%
2020 1 PoC

<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>